PT-2024-4253 · Synology · Synology Surveillance Station

Team.Envy

·

Published

2024-03-27

·

Updated

2025-08-12

·

CVE-2024-29241

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Synology Surveillance Station versions prior to 9.2.0-9289 Synology Surveillance Station versions prior to 9.2.0-11289
Description The issue is related to a missing authorization vulnerability in the System webapi component of Synology Surveillance Station. This vulnerability can be exploited by a remote attacker to bypass security constraints, potentially allowing them to elevate their privileges. The vulnerability can be exploited by remote authenticated users via unspecified vectors.
Recommendations For Synology Surveillance Station versions prior to 9.2.0-9289, update to version 9.2.0-9289 or later. For Synology Surveillance Station versions prior to 9.2.0-11289, update to version 9.2.0-11289 or later. As a temporary workaround, consider restricting access to the System webapi component until a patch is available.

Fix

Incorrect Authorization

Missing Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-04740
CVE-2024-29241

Affected Products

Synology Surveillance Station